Description
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP-Members Membership Multiple Cross-Site Scripting Vulnerabilities (2.8.9)
WordPress Plugin WP Editor.md Cross-Site Scripting (1.6)
Drupal Core 8.x Multiple Vulnerabilities (8.0.0 - 8.2.2)
WordPress Plugin Keyword Strategy Internal Links Multiple Cross-Site Scripting Vulnerabilities (2.0)